PRIVACY POLICY

 

DATA IDENTIFYING THE DATA CONTROLLER

Data controller: Irene Otero Muras

Identification Number: 53173862R

Postal Address: Eduardo Cabello 6, 36208 Vigo

Telephone: 651400743

E-mail: ireneotero@iim.csic.es

Activity: researcher (CSIC scientist)

 

INFORMATION TO WEBSITE USERS AND CONSENT

In accordance with the provisions of the European Data Protection Regulation (EU) 2016/679 and the Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights, by accepting this privacy policy the user expresses their express, free, informed and unequivocal consent for the personal data that they may provide through the contact channels and forms that may be available on the website to be incorporated into the files of the owner. The data controller informs the interested parties that, as established by the applicable regulations in force, the corresponding technical and organisational security measures have been applied to the personal data processing activities carried out, which have been implemented after the relevant risk analysis has been carried out.

 

WHAT PERSONAL DATA IS COLLECTED ON THE WEBSITE?

Through the website we collect user identification data in order to contact and manage queries and/or requests for information or related to the provision of the services developed.

The personal data collected will be processed on the following bases of legitimacy:

  • The user’s consent in relation to contact, the management of appointment requests, the sending of CVs and the sending of commercial or advertising communications, via e-mail, cookies or messaging systems.

 

  • The execution of a contract or service agreement with Irene Otero Muras to enable the development and management of the services requested.

 

WHAT IS THE PURPOSE FOR WHICH WE PROCESS THE PERSONAL DATA COLLECTED?

The personal data collected by the data controller through the means of contact provided on the website will be processed for specific purposes in each case and in accordance with the following:

Contact form: contact forms may be available on the website for queries, suggestions, requests for information or appointments or for professional contact. In this case, e-mail will be used in order to respond to the requests received and send the information requested by the user through the website.

 

HOW LONG WILL WE KEEP THE PERSONAL DATA COLLECTED?

The personal data provided to the data controller will be kept at least and generally for as long as the service provision relationship is maintained and/or the data is needed for the development of the activities of the owner and the execution of the services requested, and as long as the deletion of the data is not requested or the consent of the interested parties is not revoked.

With regard to personal data provided by data subjects, the specific statutes of limitation periods provided for in each case shall apply, with a generic period of 5 years for personal actions without a special period, 6 years for invoices and company accounting books and 10 years in relation to the provisions of the Law on the Prevention of Money Laundering and Terrorist Financing (art. 25).

 

WHAT IS THE LEGITIMATE BASIS THAT ALLOWS US TO PROCESS THE DATA COLLECTED?

The legal basis of legitimacy that allows us to process the personal data collected through the website is based, with regard to the sending of contact forms with requests for information or appointments, or the sending of CVs, on the express and informed consent of the data subject or their representative, collected and granted in accordance with the conditions indicated in art. 7 of the European Data Protection Regulation, according to which data subjects have the right to withdraw this consent at any time. The data controller informs that the data requested through the web forms will be those strictly necessary to deal with the specific query or request made by the interested party.

 

WHAT ARE THE RIGHTS THAT CAN BE EXERCISED BY THOSE WHO PROVIDE US WITH THEIR DATA?

In accordance with the provisions of the European Data Protection Regulation (EU) 2016/679 and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights, data subjects shall have the right to obtain confirmation as to whether or not we are processing personal data concerning them at www.noisynbio.org, as well as to exercise the rights recognised in relation to their data.

Interested parties shall be entitled in particular to:

  • Request access to personal data concerning him/her
  • Request rectification or deletion of data
  • Request cancellation of data
  • Request the restriction of data processing
  • Object to the processing of data
  • Request data portability

In the event that the data subject has given consent for a specific purpose, he or she shall have the right to withdraw the consent previously given at any time, without affecting the lawfulness of the processing operations based on the consent given prior to its withdrawal.

If data subjects consider that we have not processed their personal data in accordance with the aforementioned reference regulations, and if they understand that we have not satisfied their request to exercise their rights, they may, if they so wish, lodge a complaint with the Spanish Data Protection Agency as the national supervisory authority at the organisation’s address at Calle Jorge Juan, 6 – 28001 – Madrid or through the contact channels indicated on the institution’s website (www.aepd.es), including the electronic headquarters.

In order to exercise all the aforementioned rights, interested parties may contact the contact addresses indicated above to request the application form provided by the data controller for this purpose in compliance with its legal obligations, which form must be accompanied by a copy of their ID card or equivalent document accrediting their identity and that of their representative, if applicable.

The exercise of the rights will be free of charge, and the request may be delivered by hand, or sent by post or e-mail to the contact addresses indicated.

The data controller informs data subjects that it has established and implemented specific protocols and measures for compliance with the data protection regulations of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights.

 

TO WHICH RECIPIENTS MAY YOUR DATA BE DISCLOSED?

The personal data provided by users will only be processed in general by the person responsible for the activity and by the company’s own employees and any authorised freelance collaborators that may be contracted.

Some of the tools used by the website to manage data have been contracted to third parties for the provision of services developed by them and which are necessary for the activity of the party responsible.

Occasional access to the website may be granted to the development or maintenance company of the website itself or to the hosting company, with which, in any case, the corresponding service provision contract has been formalised, obliging them to maintain the appropriate level of privacy.

In any case, in general, data will only be transferred to third parties in cases of legal obligation, such as transfers made to Public Authorities and Administrations, or when this is necessary to enable the development of the services of the controller and/or the services contracted from external suppliers, including banks, financial institutions, mutual and insurance companies, and data processors, and always in this case within the framework provided for in the data processor contract formalised between the controller and the contracted data processors. The data controller undertakes in all cases to inform data subjects of the need for extraordinary transfers of data to third parties in order to manage the provision of services, so that data subjects may express their consent to the transfer of data as a prerequisite for the transfer to be carried out.

In the case of international data transfers derived from the use of tools or service providers, they will be carried out under the protection of the international conventions and agreements in force at any given time, which guarantee that North American and non-EU software companies comply with European data protection policies in terms of privacy, secrecy and data security.

 

DATA SECRECY AND SECURITY

Irene Otero Muras undertakes to use and process users’ personal data appropriately, respecting their confidentiality, and to use them in accordance with the purpose of said processing, as well as to comply with its obligation to store the data and to adapt all the measures in place to avoid their alteration, loss, unauthorised processing or access, and in accordance with the provisions of current data protection regulations.

This website includes an SSL certificate, a security protocol that makes your data travel in an integral and secure way, that is to say, the transmission of data between a server and a user of the website, and in feedback, is totally encrypted or encrypted.

The responsible party cannot guarantee the absolute impregnability of the Internet network and therefore the violation of the data through fraudulent access to them by third parties.

Regarding the confidentiality of data processing, Irene Otero Muras will ensure that any person who is authorised to process the data of data subjects and/or users, including staff, collaborators and suppliers, is under the corresponding obligation of confidentiality, whether legal or contractual.

When a security incident occurs, once Irene Otero Muras becomes aware of it, it will notify the interested party without undue delay and will provide the appropriate information related to the security incident and in any case whenever the interested party requests it in a reasonable manner.

 

ACCURACY AND VERACITY OF DATA

The user is solely responsible for the veracity and correctness of the personal data that he/she sends or sends through www.noisynbio.org, exonerating Irene Otero Muras of any responsibility in this respect. Users guarantee and are responsible, in any case, for the accuracy, validity and authenticity of the personal data provided, and undertake to keep them duly updated. The user agrees to provide complete and correct information in the contact form.

 

CHANGES TO THE PRIVACY POLICY

Irene Otero Muras reserves the right to modify this privacy policy to adapt it to new legislation or jurisprudence, as well as to the practices of the sector. In these cases, the changes will be announced on the website with due notice before they are put into practice.

 

Privacy Policy updated as of 1 July 2021

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.